Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2015-0235 | First vendor Publication | 2015-01-28 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0235 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-787 | Out-of-bounds Write (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:28360 | |||
Oval ID: | oval:org.mitre.oval:def:28360 | ||
Title: | RHSA-2015:0090 -- glibc security update (Critical) | ||
Description: | The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the Name Server Caching Daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. A heap-based buffer overflow was found in glibc's __nss_hostname_digits_dots() function, which is used by the gethostbyname() and gethostbyname2() glibc function calls. A remote attacker able to make an application call either of these functions could use this flaw to execute arbitrary code with the permissions of the user running the application. (CVE-2015-0235) Red Hat would like to thank Qualys for reporting this issue. All glibc users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2015:0090 CESA-2015:0090 CVE-2015-0235 | Version: | 3 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 | Product(s): | glibc |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:28438 | |||
Oval ID: | oval:org.mitre.oval:def:28438 | ||
Title: | RHSA-2015:0092 -- glibc security update (Critical) | ||
Description: | The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the Name Server Caching Daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. A heap-based buffer overflow was found in glibc's __nss_hostname_digits_dots() function, which is used by the gethostbyname() and gethostbyname2() glibc function calls. A remote attacker able to make an application call either of these functions could use this flaw to execute arbitrary code with the permissions of the user running the application. (CVE-2015-0235) Red Hat would like to thank Qualys for reporting this issue. All glibc users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2015:0092 CESA-2015:0092-CentOS 6 CESA-2015:0092-CentOS 7 CVE-2015-0235 | Version: | 3 |
Platform(s): | Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 CentOS Linux 6 CentOS Linux 7 | Product(s): | glibc |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:28503 | |||
Oval ID: | oval:org.mitre.oval:def:28503 | ||
Title: | USN-2485-1 -- GNU C Library vulnerability | ||
Description: | It was discovered that a buffer overflow existed in the gethostbyname and gethostbyname2 functions in the GNU C Library. An attacker could use this issue to execute arbitrary code or cause an application crash, resulting in a denial of service. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-2485-1 CVE-2015-0235 | Version: | 3 |
Platform(s): | Ubuntu 12.04 Ubuntu 10.04 | Product(s): | eglibc |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:28528 | |||
Oval ID: | oval:org.mitre.oval:def:28528 | ||
Title: | DSA-3142-1 -- eglibc -- security update | ||
Description: | Several vulnerabilities have been fixed in eglibc, Debian's version of the GNU C library. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-3142-1 CVE-2012-6656 CVE-2014-6040 CVE-2014-7817 CVE-2015-0235 | Version: | 3 |
Platform(s): | Debian GNU/Linux 7.0 Debian GNU/kFreeBSD 7.0 | Product(s): | eglibc |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:28622 | |||
Oval ID: | oval:org.mitre.oval:def:28622 | ||
Title: | ELSA-2015-0092 -- glibc security update (critical) | ||
Description: | [2.17-55.0.4.el7_0.5] - Remove strstr and strcasestr implementations using sse4.2 instructions. - Upstream commits 584b18eb4df61ccd447db2dfe8c8a7901f8c8598 and 1818483b15d22016b0eae41d37ee91cc87b37510 backported. (Jose E. Marchesi) [2.17-55.5] - Rebuild and run regression testing. [2.17-55.4] - Fix parsing of numeric hosts in gethostbyname_r (CVE-2015-0235, #1183535). [2.17-55.3] - Fix wordexp() to honour WRDE_NOCMD (CVE-2014-7817, #1170118) [2.17-55.2] - ftell: seek to end only when there are unflushed bytes (#1170187). [2.17-55.1] - Remove gconv transliteration loadable modules support (CVE-2014-5119, - _nl_find_locale: Improve handling of crafted locale names (CVE-2014-0475, | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2015-0092 CVE-2015-0235 | Version: | 3 |
Platform(s): | Oracle Linux 6 Oracle Linux 7 | Product(s): | glibc |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:28638 | |||
Oval ID: | oval:org.mitre.oval:def:28638 | ||
Title: | ELSA-2015-0090 -- glibc security update (critical) | ||
Description: | [2.5-123.0.1.el5_11.1] - Switch to use malloc when the input line is too long [Orabug 19951108] - Use a /sys/devices/system/cpu/online for _SC_NPROCESSORS_ONLN implementation [Orabug 17642251] (Joe Jin) [2.5-123.1] - Fix parsing of numeric hosts in gethostbyname_r (CVE-2015-0235, #1183532). | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2015-0090 CVE-2015-0235 | Version: | 3 |
Platform(s): | Oracle Linux 5 | Product(s): | glibc |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Snort® IPS/IDS
Date | Description |
---|---|
2016-09-27 | WordPress pingback gethostbyname heap buffer overflow attempt RuleID : 39925 - Revision : 2 - Type : SERVER-WEBAPP |
2015-03-04 | WordPress pingback gethostbyname heap buffer overflow attempt RuleID : 33275 - Revision : 2 - Type : SERVER-WEBAPP |
2015-03-04 | Exim gethostbyname heap buffer overflow attempt RuleID : 33226 - Revision : 3 - Type : SERVER-MAIL |
2015-03-04 | Exim gethostbyname heap buffer overflow attempt RuleID : 33225 - Revision : 4 - Type : SERVER-MAIL |
Metasploit Database
id | Description |
---|---|
2020-05-23 | WordPress XMLRPC GHOST Vulnerability Scanner |
2015-01-27 | Exim GHOST (glibc gethostbyname) Buffer Overflow |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2017-12-04 | Name : The remote host is missing a vendor-supplied security patch. File : check_point_gaia_sk104443.nasl - Type : ACT_GATHER_INFO |
2016-07-19 | Name : The remote device is affected by a remote code execution vulnerability. File : cisco-sa-20150128-ghost-nxos.nasl - Type : ACT_GATHER_INFO |
2016-02-17 | Name : The remote OracleVM host is missing one or more security updates. File : oraclevm_OVMSA-2016-0013.nasl - Type : ACT_GATHER_INFO |
2015-12-11 | Name : The remote multi-function device is affected by multiple vulnerabilities. File : xerox_xrx15r.nasl - Type : ACT_GATHER_INFO |
2015-12-11 | Name : The remote multi-function device is affected by multiple vulnerabilities. File : xerox_xrx15ad_colorqube.nasl - Type : ACT_GATHER_INFO |
2015-11-10 | Name : The remote host is missing a Mac OS X update that fixes multiple security vul... File : macosx_SecUpd2015-007.nasl - Type : ACT_GATHER_INFO |
2015-10-29 | Name : The remote host is missing a Mac OS X update that fixes multiple security vul... File : macosx_10_11_1.nasl - Type : ACT_GATHER_INFO |
2015-10-05 | Name : The remote host is missing a Mac OS X update that fixes multiple security vul... File : macosx_10_11.nasl - Type : ACT_GATHER_INFO |
2015-09-18 | Name : The remote device is missing a vendor-supplied security patch. File : f5_bigip_SOL16057.nasl - Type : ACT_GATHER_INFO |
2015-08-17 | Name : The remote host is missing a vendor-supplied security patch. File : cisco_cups_CSCus69785.nasl - Type : ACT_GATHER_INFO |
2015-07-01 | Name : The remote host is missing a Mac OS X update that fixes multiple security vul... File : macosx_SecUpd2015-005.nasl - Type : ACT_GATHER_INFO |
2015-07-01 | Name : The remote host is missing a Mac OS X update that fixes multiple security vul... File : macosx_10_10_4.nasl - Type : ACT_GATHER_INFO |
2015-03-26 | Name : The remote Debian host is missing a security update. File : debian_DLA-139.nasl - Type : ACT_GATHER_INFO |
2015-03-25 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2015-494.nasl - Type : ACT_GATHER_INFO |
2015-03-17 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2015-493.nasl - Type : ACT_GATHER_INFO |
2015-03-09 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201503-04.nasl - Type : ACT_GATHER_INFO |
2015-03-05 | Name : The remote Fedora host is missing a security update. File : fedora_2015-2328.nasl - Type : ACT_GATHER_INFO |
2015-03-02 | Name : The remote device is missing a vendor-supplied security patch. File : cisco-sa-20150128-ghost-iosxr_NCS6K.nasl - Type : ACT_GATHER_INFO |
2015-03-02 | Name : The remote device is missing a vendor-supplied security patch. File : cisco-sa-20150128-ghost-iosxe_nova.nasl - Type : ACT_GATHER_INFO |
2015-03-02 | Name : The remote device is missing a vendor-supplied security patch. File : cisco-sa-20150128-ghost-iosxe_multi.nasl - Type : ACT_GATHER_INFO |
2015-02-27 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_f7a9e415bdca11e4970c000c292ee6b8.nasl - Type : ACT_GATHER_INFO |
2015-02-26 | Name : The remote device is affected by a buffer overflow vulnerability. File : cisco_cucm_CSCus66650-GHOST.nasl - Type : ACT_GATHER_INFO |
2015-02-25 | Name : The remote web server uses a version of PHP that is affected by multiple vuln... File : php_5_6_6.nasl - Type : ACT_GATHER_INFO |
2015-02-25 | Name : The remote web server uses a version of PHP that is affected by multiple vuln... File : php_5_5_22.nasl - Type : ACT_GATHER_INFO |
2015-02-25 | Name : The remote web server uses a version of PHP that is affected by multiple vuln... File : php_5_4_38.nasl - Type : ACT_GATHER_INFO |
2015-02-24 | Name : The remote Fedora host is missing a security update. File : fedora_2015-2315.nasl - Type : ACT_GATHER_INFO |
2015-02-20 | Name : The remote device is affected by a buffer overflow vulnerability. File : cisco-sa-20150128-ace.nasl - Type : ACT_GATHER_INFO |
2015-02-18 | Name : The version of Cisco TelePresence Video Communication Server installed on the... File : cisco_telepresence_vcs_CSCus69558.nasl - Type : ACT_GATHER_INFO |
2015-02-18 | Name : The remote Cisco TelePresence Conductor device is affected by a buffer overfl... File : cisco_telepresence_conductor_CSCus69523.nasl - Type : ACT_GATHER_INFO |
2015-02-11 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2015-039.nasl - Type : ACT_GATHER_INFO |
2015-02-06 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2015-0126.nasl - Type : ACT_GATHER_INFO |
2015-02-04 | Name : The remote host is affected by a buffer overflow vulnerability. File : palo_alto_PAN-SA-2015-0002.nasl - Type : ACT_GATHER_INFO |
2015-02-03 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2015-84.nasl - Type : ACT_GATHER_INFO |
2015-02-02 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_glibc-9035.nasl - Type : ACT_GATHER_INFO |
2015-02-02 | Name : The remote OracleVM host is missing one or more security updates. File : oraclevm_OVMSA-2015-0024.nasl - Type : ACT_GATHER_INFO |
2015-02-02 | Name : The remote OracleVM host is missing one or more security updates. File : oraclevm_OVMSA-2015-0023.nasl - Type : ACT_GATHER_INFO |
2015-01-30 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0101.nasl - Type : ACT_GATHER_INFO |
2015-01-30 | Name : The remote OracleVM host is missing one or more security updates. File : oraclevm_OVMSA-2015-0022.nasl - Type : ACT_GATHER_INFO |
2015-01-30 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-0101.nasl - Type : ACT_GATHER_INFO |
2015-01-29 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0099.nasl - Type : ACT_GATHER_INFO |
2015-01-29 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2015-028-01.nasl - Type : ACT_GATHER_INFO |
2015-01-29 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_0765de84a6c111e4a0c1c485083ca99c.nasl - Type : ACT_GATHER_INFO |
2015-01-28 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-0090.nasl - Type : ACT_GATHER_INFO |
2015-01-28 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2485-1.nasl - Type : ACT_GATHER_INFO |
2015-01-28 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20150127_glibc_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2015-01-28 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20150127_glibc_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2015-01-28 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0092.nasl - Type : ACT_GATHER_INFO |
2015-01-28 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0090.nasl - Type : ACT_GATHER_INFO |
2015-01-28 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-0092.nasl - Type : ACT_GATHER_INFO |
2015-01-28 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3142.nasl - Type : ACT_GATHER_INFO |
2015-01-28 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-0092.nasl - Type : ACT_GATHER_INFO |
2015-01-28 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-0090.nasl - Type : ACT_GATHER_INFO |
2015-01-27 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2015-473.nasl - Type : ACT_GATHER_INFO |
2015-01-27 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_glibc-150122.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 12:44:32 |
|
2024-08-02 12:31:05 |
|
2024-08-02 01:09:13 |
|
2024-02-14 13:28:16 |
|
2024-02-02 01:30:08 |
|
2024-02-01 12:08:51 |
|
2023-09-05 12:28:38 |
|
2023-09-05 01:08:42 |
|
2023-09-02 12:28:34 |
|
2023-09-02 01:08:51 |
|
2023-08-12 12:31:09 |
|
2023-08-12 01:08:20 |
|
2023-08-11 12:26:41 |
|
2023-08-11 01:08:33 |
|
2023-08-06 12:25:55 |
|
2023-08-06 01:08:19 |
|
2023-08-04 12:25:59 |
|
2023-08-04 01:08:23 |
|
2023-07-14 12:25:59 |
|
2023-07-14 01:08:21 |
|
2023-03-29 01:27:44 |
|
2023-03-28 12:08:41 |
|
2022-10-11 12:23:25 |
|
2022-10-11 01:08:30 |
|
2022-07-06 00:28:16 |
|
2022-06-21 00:27:29 |
|
2022-06-18 00:27:30 |
|
2021-11-18 05:23:19 |
|
2021-11-10 09:23:39 |
|
2021-11-05 21:23:19 |
|
2021-09-17 01:19:45 |
|
2021-09-02 00:23:10 |
|
2021-09-01 17:23:26 |
|
2021-06-10 01:15:13 |
|
2021-05-05 00:23:04 |
|
2021-05-04 12:39:34 |
|
2021-04-22 01:48:26 |
|
2020-12-11 01:12:22 |
|
2020-10-15 00:22:40 |
|
2020-05-23 13:17:06 |
|
2020-05-23 00:43:22 |
|
2019-06-14 05:20:26 |
|
2019-06-13 21:19:22 |
|
2019-06-13 13:19:23 |
|
2018-12-01 00:18:57 |
|
2018-10-17 09:20:14 |
|
2018-10-10 00:19:54 |
|
2017-12-05 13:24:05 |
|
2017-11-10 09:22:58 |
|
2017-10-20 09:23:00 |
|
2017-09-22 09:24:09 |
|
2017-08-09 09:23:32 |
|
2017-07-01 09:23:13 |
|
2017-01-03 09:23:03 |
|
2016-12-07 09:24:14 |
|
2016-10-26 09:22:44 |
|
2016-08-23 09:24:53 |
|
2016-08-09 09:24:04 |
|
2016-07-22 13:38:25 |
|
2016-07-22 12:03:12 |
|
2016-06-02 09:25:34 |
|
2016-04-07 09:21:47 |
|
2016-02-18 13:27:47 |
|
2016-01-22 09:22:20 |
|
2015-12-12 13:26:16 |
|
2015-12-05 13:26:50 |
|
2015-11-11 13:25:48 |
|
2015-11-06 00:22:26 |
|
2015-10-30 13:24:08 |
|
2015-10-24 09:22:36 |
|
2015-10-23 09:23:23 |
|
2015-10-10 09:23:21 |
|
2015-10-07 13:24:30 |
|
2015-09-19 13:23:28 |
|
2015-08-19 13:30:10 |
|
2015-08-18 13:34:55 |
|
2015-07-17 09:19:41 |
|
2015-07-06 09:25:53 |
|
2015-07-02 13:28:44 |
|
2015-04-17 09:27:58 |
|
2015-04-07 09:27:34 |
|
2015-04-01 09:27:08 |
|
2015-03-31 09:27:15 |
|
2015-03-27 13:28:58 |
|
2015-03-27 09:27:27 |
|
2015-03-26 13:27:40 |
|
2015-03-24 09:29:22 |
|
2015-03-21 05:25:36 |
|
2015-03-18 13:27:29 |
|
2015-03-18 09:28:39 |
|
2015-03-17 09:27:11 |
|
2015-03-11 13:24:59 |
|
2015-03-10 13:25:12 |
|
2015-03-06 13:25:58 |
|
2015-03-04 21:23:17 |
|
2015-03-03 13:25:19 |
|
2015-02-28 13:24:16 |
|
2015-02-27 13:24:26 |
|
2015-02-26 13:24:24 |
|
2015-02-25 13:24:11 |
|
2015-02-21 13:24:20 |
|
2015-02-19 13:24:57 |
|
2015-02-19 09:23:52 |
|
2015-02-13 17:23:25 |
|
2015-02-12 13:24:00 |
|
2015-02-12 00:22:57 |
|
2015-02-07 13:25:14 |
|
2015-02-06 09:23:16 |
|
2015-02-05 13:23:48 |
|
2015-02-04 13:24:41 |
|
2015-02-03 13:24:17 |
|
2015-01-31 13:23:09 |
|
2015-01-30 21:22:51 |
|
2015-01-30 13:24:25 |
|
2015-01-29 21:26:27 |
|
2015-01-29 13:24:21 |
|
2015-01-29 00:24:14 |
|